Resources / Azure Azure Governance Hierarchy Component Map Last updated: September 03, 2026 governance azure rbac policy subscriptions tagging practical Related guides Azure Subscription & Tenant Architecture Azure Resource Organization & Tagging Azure Policy and Governance Azure RBAC & Managed Identities Containment and Inheritance Azure governance hierarchy and what inherits down it Nested boxes from Entra ID tenant down to an individual resource, beside four rails showing that RBAC and Policy inherit from management group down, locks from subscription down, and tags do not inherit at all. EVERYTHING LIVES INSIDE THE THING ABOVE IT Entra ID Tenant identity and authentication boundary Root Management Group created automatically, one per tenant Management Group up to 6 levels below root Subscription billing + access + quota, all at once Resource Group delete it and everything inside goes Resource exactly one resource group region is its own, not the group's WHAT FLOWS DOWN, AND FROM WHERE RBAC Policy Locks Tags ✗ RBAC · additive, a lower scope never subtracts Policy · Deny blocks the write before it happens Locks · beat RBAC, even an Owner cannot delete Tags · do NOT inherit, Policy must copy them ✗ moving a resource changes its ID, so RBAC assignments, alerts and automation that name it break ✗ a lock has to come off before a move, and deny assignments cannot be authored by you at all Found this useful? Share it: Share on LinkedIn